MQTT/Staying connected/Postcards and strangers

Postcards and strangers

A broker takes messages from anyone who can reach it, and plain MQTT carries everything, the password included, as readable text. Usernames keep strangers out; TLS seals the envelopes.

Everything in this course has assumed that only your own devices talk to your broker. The broker assumes nothing of the kind. A client that can reach it can post to any topic, including home/lamp/set, unless it is told otherwise.

Checking ID

The first defence is a username and password. The client sends them in its CONNECT, and the broker refuses a client that has none, or the wrong ones. Brokers can go further and say which user may post or subscribe to which topics, so that the sensor may post home/kitchen/temp and nothing else.

Mosquitto, the broker most people start with, has refused anonymous clients by default since version 2.0, in December 2020: started with no settings at all, it listens only to the computer it runs on, and any listener you open turns away a client without a username unless you configure allow_anonymous true. Older guides tell you to do exactly that.

Postcards

The second problem is that plain MQTT, on port 1883, encrypts nothing. Every packet is readable by anything on the path it takes — the topic, the payload, and the username and password in the CONNECT. It is a postcard.

TLS is the sealed envelope: the same MQTT, inside an encrypted connection, usually on port 8883. The broker proves who it is with a certificate, and nothing on the way can read what is inside or change it.

A postcard lying face up beside a sealed envelope on a dark desk
Plain MQTT is a postcard; TLS is the sealed envelope.Generated illustration

Where to put a broker

  • On your own network, reachable only from inside it, a password is a sensible minimum.
  • Reachable from the internet, it needs both: passwords and TLS. Or keep it inside, and reach it from outside through a VPN.
  • Never a broker on the open internet with neither. Anything that finds it can read every reading and switch every lamp.

That is the whole course: a post office, what goes on the envelope, who gets a copy, what is kept, how careful the delivery is, how the post office knows you are there, what it says when you vanish, and who it lets in. The ESP32 book's MQTT chapter puts it on a board.

Common mistakes

  • Port-forwarding 1883 to reach home from outside. That puts a postcard broker on the internet.
  • allow_anonymous true copied from an old guide and never removed.
  • Checking the certificate off to make TLS connect. The envelope is sealed, but anybody can pretend to be the post office.

Edit this page — content/fundamentals/mqtt/postcards-and-strangers.mdx

Discuss this article

Ask about this page. The answer stays here, on the page it belongs to, for whoever hits the same wall next.

Browse Fundamentals on the forum →